CVE-2023-46846
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Nov 3, 2023
Updated: Dec 18, 2024
CWE ID 444
Summary
CVE-2023-46846 is a newly disclosed vulnerability affecting the SQUID proxy server. This issue arises due to the server's lenient handling of chunked transfer encoding, enabling a remote attacker to perform HTTP request smuggling. The attacker can inject malicious requests, bypassing security systems like firewalls and frontend proxies, leading to significant security risks. This vulnerability requires careful attention and immediate patching to prevent potential unauthorized access or data manipulation.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Squid Software
- Squid-cache Squid
- Red Hat Enterprise Linux
- Redhat Enterprise Linux For Ibm Z Systems
Affected Vendors
- Red Hat
- Squid Software Foundation